CVE-2008-2833

Worldlevel Le.cms < 1.4 - Authentication Bypass

Title source: rule

Description

admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload and execute arbitrary files in images/, via a nonzero value for the submit0 parameter in conjunction with filenames in the filename and upload parameters.

Exploits (1)

exploitdb WORKING POC VERIFIED
by t0pP8uZz · perlwebappsphp
https://www.exploit-db.com/exploits/5887

Scores

EPSS 0.0442
EPSS Percentile 88.9%

Classification

CWE
CWE-287
Status draft

Affected Products (1)

worldlevel/le.cms < 1.4

Timeline

Published Jun 24, 2008
Tracked Since Feb 18, 2026